Onsera App Privacy Policy


Last updated: February 19, 2026

We value your trust and are committed to protecting your privacy. This Privacy Policy (“Privacy Policy”) explains the ways in which your personal information may be collected, stored, utilized, and shared in connection with your use of the products and services of Onsera, LLC (“Onsera,” “Onsera Health,” “we” or “us”), including the Onsera Mobile App (“Onsera App” or “Application”), the images and content provided via the Onsera App, and any other Onsera-owned websites (collectively, the “Services”). In addition, this Privacy Policy describes the steps we take to protect your personal information. By using the Services, you are expressly agreeing that you have read and understood this Privacy Policy. Please read this Privacy Policy carefully. Onsera Health Privacy Notice Your privacy is important to us. Please read this Privacy Notice (“Policy”) and any other privacy notice or fair processing notice Onsera Health, Inc. (“Onsera”, “we” and “us”) may provide on specific occasions carefully, as it is meant to help you understand what information we collect, why we collect it, how we process it and your rights. This Policy has been drafted as to be applied to personal information processing activities globally in compliance with US Law and the EU General Data Protection Regulation (GDPR). This Policy supplements our other notices and is not intended to override them.

Please also review our Terms of Use for additional terms and conditions applicable to the Services.

BY DOWNLOADING, ACCESSING, OR USING THE ONSERA APP OR SERVICES, AND/OR BY REGISTERING WITH US OR PROVIDING INFORMATION TO US IN CONNECTION WITH THE APPLICATION, YOU ACCEPT THE PRACTICES AND POLICIES OUTLINED IN THIS PRIVACY POLICY, AND YOU HEREBY CONSENT THAT WE WILL COLLECT, USE, AND SHARE YOUR INFORMATION AS SET FORTH IN THIS PRIVACY POLICY. IF YOU ARE REGISTERING AN ACCOUNT OR USING THE SERVICES ON BEHALF OF AN INDIVIDUAL OR ENTITY OTHER THAN YOURSELF, YOU REPRESENT THAT YOU ARE AUTHORIZED BY SUCH INDIVIDUAL OR ENTITY TO ACCEPT THIS PRIVACY POLICY ON SUCH INDIVIDUAL’S OR ENTITY’S BEHALF. IF YOU DO NOT AGREE TO THIS PRIVACY POLICY, PLEASE DO NOT USE THE SERVICES."

1. Types of Information We Collect

Personal Information:
We and our affiliated service providers, including affiliated health care service providers (“Service Providers”) may collect Personal Information from you which includes general information that may directly or indirectly identify you, such as your name, date of birth, address, email address, or other identifying information.This Policy applies to ways in which we interact with individuals, which we referred to herein as “Data Subjects”, in connection with our business, including, without limitation:

Protected Health Information (“PHI”):
We and our Service Providers may also collect PHI which includes information that may be used to identify you and that was created, used, or disclosed in the course of providing a health care service. In certain contexts, PHI is protected under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”). HIPAA and other laws regulate the protection of PHI and how it may be handled and shared. Onsera may offer certain Services to you through a relationship with your employer, health care provider, or other entity covered by the privacy and security requirements of the HIPAA law (i.e., a “Sponsored Program”). Onsera ensures that it complies with HIPAA when offering Services in connection with a Sponsored Program.

General Usage Information:
Onsera also collects General Usage Information, which is other information that, by itself, does not individually identify you, such as your operating system, device type, server logs, app navigation data, use data, access data, technical data, and other usage information. We may link different types of General Usage Information together or link General Usage Information to Personal Information.

2. How We Collect Information

Onsera collects information in the following ways:
Information you give us:
When you sign up for a Onsera Account you will provide your e-mail address and complete a brief survey including your date of birth, gender, height, weight, and lifestyle habits. We may also collect information such as your general geographic location or your preferred means of communication when you voluntarily provide us with such information. You may then choose to directly link additional information including wearable fitness tracker data, insurance information, electronic medical records, pharmacy records, and lab data. Occasionally, you may be asked to complete additional health or lifestyle surveys.  We may also collect billing information, Shipping address, Debit and Credit card details, Commercial information such as purchases, Customer service information, such as information about your customer service and maintenance interactions with us, information about others such as family, friends etc. We may also collect Sensitive Personal Information including but not limited to lifestyle choices, Sex life and sexual orientation, Login Credentials, drug or alchohol use, genetics etc. or user-generated content you post in public online forums on our Services or disclose to other users or your healthcare providers, Contents of Communications such as Chats. 

If you invite family, friends or other third parties to be part of your team or join your chat sessions with your health coach, they will have access to the information disclosed during that session. You should also be aware that certain features within the Services allow for group chat sessions or public forums. By inviting any third parties to join your chat sessions or participate in group session or public forums, you consent to the disclosure of your information, including information about your health and any health conditions to the other participants. We cannot control whether or how these participants will use your information or if they will subsequently disclose it. If you do not consent to the disclosure of this information to these third parties, you should not invite them to join your team or participate in the group sessions or other public forums.

Also Information can be collected through:
  • Processing your orders and requests for treatment, including orders and requests made by your provider in connection with your care. 
  • Requests for customer support and technical assistance, including through online chat functionalities 
  • Employment applications you submit
Information obtained from your employer or health care provider:
When you access Onsera in connection with a Sponsored Program, Onsera and its affiliated Service Providers may collect certain Personal Information or PHI, such as your name, date of birth, gender, mailing address, health coverage details, health plan identification number, medical claims data, and other information from or on behalf of your employer, or your past, current, and future health care providers. We use this information only in accordance with your express authorization, which we request from you through a separate document before you access the Services

Information obtained from other sources:
We may obtain information about you from affiliates, partners, and other third-parties. This information may be used to provide services to you and to provide analysis about you in comparison to people who are demographically similar to you. We may combine the information we obtain from third-parties with information that we have collected about you.

Information we get from your use of the Services:
We may collect information about the Services that you use and how you use them. This information includes:

Computer, tablet, or mobile telephone information:
We may collect device-specific information (such as your hardware model, operating system, unique device identifiers, device sensors and mobile network information including phone number) and device sensors and related device hardware. Onsera may associate your device identifiers or phone number with your Onsera Account

Information from wearables:
When you connect your wearable fitness tracker, heart rate monitor, pedometer or other wearable technology with the Services, we collect information about your steps, fitness activities, exercise frequency, sleep, and information about nutrition, such as caloric intake, nutritional statistics, blood pressure, and other biometric data

Log information:
When you use the Services or view content provided by Onsera, we may automatically collect and store certain information in server logs. This may include:
  • Internet protocol address.
  • Device information such hardware settings, duration of use, app navigation data, system activity, and device crashes.
  • Cookies that may uniquely identify your Onsera Account. We may also collect information through our App and variety of technologies, and may include automated tools including cookies, SDKs, and similar tools, Third Party Web Beacons and Third Party Buttons, tracking pixels, and other similar tracking technologies to assist in collecting this information.
  • Information collected from websites including platform type, the number of clicks, files you download, domain names, landing pages, pages viewed and the order of those pages, the amount of time spent on particular pages, the terms you use in searches on our sites, the date and time you used the Services, error logs, and other similar information.
  • Information collected from your social media platforms
  • We may use AI based models to process data, provide tailored responses. The data shall be handled in accordance with our data governance standards. Responses generated by the AI are specifically based on the information provided during your use of the service. We may retain the data provided by you with AI dialogues for use in future and provide better services to you.
  • We may collect, analyze, use, publish, create and sell de-identified information, for any business or other purpose not prohibited by applicable law, including for research and marketing purposes
Location information:
When you use a location-enabled feature within the Onsera Mobile App (“Onsera App”), we may collect and process information about your GPS location sent by your mobile device. We may also use other mobile device features to determine your location, such as features that provide information on nearby Wi-Fi access points and cell towers.

Unique application numbers:
When you install or uninstall the Onsera App (or when the App periodically communicates with our servers for updates) information such as the operating system type, application version number, and a unique application number may be sent to Onsera.

Local storage:
We may collect and store information locally on your device using application data caches.


3. How We Use Information We Collect

To provide Services to you:
We and our Service Providers use the information that we collect about you to provide, maintain, protect and improve the Services that Onsera provides to you. This includes services which ensure and enable  the health care providers and physicians to provide services to you, verifying your identity, processing of your payments, fulfilling your orders, use of information of internal research purposes, advertising and marketing  services, communicate with you the services provided by parent and affiliates companies. 

To provide Sponsored Programs to you:
We and our Service Providers may use the information that we collect about you to provide Services through Sponsored Programs in collaboration with your employer.

Because General Usage Information does not personally identify you, we may use General Usage Information for any purpose. In instances where we may combine General Usage Information with Personal Information (such as combining your zip code with your name), the combined information will be treated by us as Personal Information as long as it is so combined. The information may also be use for legal purposes. Further we may combine, aggregate, de- Indentify the information, use online analytics to process and use such information , use online advertising tools for using the said information for advertising purposes.  

We may use your information for Product and service delivery, Business Operations, Product imporovement and research, Personalisation, Customer support, Communications. Marketing and Advertising


4. What Information We Share

We take your privacy seriously. We do not sell your information to any third-parties and all information disclosed to any third-party is the minimum amount necessary to fulfill the legitimate business purpose. We do not share Personal Information with companies, organizations or individuals outside of Onsera except in the following circumstances:

With your consent:
We may share your Personal Information with companies, organizations or individuals outside of Onsera when we have your consent to do so.

As part of a Sponsored Program:
Onsera may share your Personal Information with your employer, health plan, or health care provider in the following contexts:

Plan administration:
Under applicable U.S. laws, we may share PHI with your health plan for the administration of your plan.

Healthcare providers:
We may share information with your Service Providers. Our disclosure of your Personal Information may also be subject to certain restrictions set forth in agreements between us and your Service Providers

Your employer:
We will not share your PHI with your employer for any employment-related purpose. We may share certain limited Personal Information with your employer that is needed to deliver a Sponsored Program. For example, we may share completion status of a Sponsored Program requirement but not the actual results of the required action.

Third-party service providers:
Onsera does not sell or rent your PHI to third parties. We may disclose your PHI to our business associates including nutrition coaches who perform various functions on our behalf and who have agreed in writing to safeguard your PHI appropriately and in accordance with the law. We also may disclose your Personal Information to third-parties in the following limited contexts:

For external services:
We provide Personal Information to our affiliates or other trusted businesses or persons who provide services to you or us, based on our instructions and in compliance with our Privacy Policy and any other appropriate confidentiality and security measures. We may disclose information to Affiliates and subsidiaries, Health Care providers and Services, Service Providers, Advertising networks, Marketing Partners, Business Transfers etc. disclose payment and transactional data to banks and other entities as necessary for payment processing, fraud prevention, credit risk reduction, analytics, or other related financial services. Third party analytics and advertising companies also collect personal data through our website and apps. 

We may disclose the same as part of a corporate transaction or proceeding such as a merger, financing, acquisition, bankruptcy, dissolution, or a transfer, divestiture, or sale of all or a portion of our business or assets.

For legal reasons:
We will share Personal Information with companies, organizations or individuals outside of Onsera if we have a good-faith belief that access, use, preservation or disclosure of the information is reasonably necessary to:
Other services:
Other services, at your direction, when you decide to link your account with us to those services. If you link your account to any of those third parties, or allow us to share your information with them, that data is governed by their privacy policies.

Transferring of Information:
The information we collect may be stored and processed in your country or region, or in any other country where we or our affiliates, subsidiaries, or service providers process data. Currently, we primarily use data centers in the _____________(example US). These locations were chosen to operate efficiently and improve our performance.

We take steps to protect your information as described in this policy wherever the data are located, some of which have not been determined by the _______________ (Example - European Commission) to have an adequate level of data protection. When we do so, we use legal mechanisms, including contracts, to help ensure your rights and protections.

If Onsera is involved in a merger, acquisition or asset sale, we will continue to ensure the confidentiality of any Personal Information and give affected users notice before Personal Information is transferred or becomes subject to a different privacy policy.


5. How We Protect Your Information

Onsera is committed to protecting the sensitive user information held on its platform from unauthorized access, alteration, disclosure, or destruction. Specifically, Onsera has taken the following steps to protect your information from unauthorized disclosure:


6. Your Control of Your Information

Exporting Personal Information.
As a Onsera user, you have the option to cancel your account and/or to export your Personal Information at any time by contacting Onsera Customer Support.

Updating or correcting Personal Information:
Our goal is to give users ways to update and correct their information quickly or, alternatively, delete the information, unless we need to keep the information for legitimate business or legal purposes. When updating your Personal Information, we may ask you to verify your identity before we can act on your request. Where we can provide information access and correction, we will do so for free, except where it would require a disproportionate effort. We aim to maintain our Services in a manner that protects information from accidental or malicious destruction. Because of this, after you delete information from our Services, we may not immediately delete residual copies from our active servers and may not remove information from our backup systems. Access, correction, or deletion requests can be made by contacting Onsera Customer Support

Account Closures:
Upon termination (by you or by Onsera) of a relationship with a Service Provider supporting a Sponsored Program (e.g. termination of your employment or cessation of the program), you will no longer have access to your Onsera Account or the Personal Information generated during the Sponsored Program. Upon account closure, you have the option to export your Personal Information by contacting Onsera Customer Support.

Providing Access:
Access to the information that we have collected about you and a copy of certain information in a portable format. 

Right Against Discrimination:
We will never discriminate against you for exercising these rights. You may designate, in writing or through a power of attorney, an authorized agent to exercise these rights on your behalf. Before accepting such a request from an agent, we will require the agent to provide proof you have authorized them to act on your behalf, and we may need you to verify your identity directly with us.


7. How Long we Store Your Information

Generally we keep your information only so long as we need it to provide our services to you, fulfill the purposes described in this policy, comply with our legal obligations, resolve disputes, and enforce our agreements. Actual retention periods can vary significantly based on your expectations and consent, the sensitivity of the data, the availability of automated controls, and our legal or contractual obligations.


8. Not Intended for Users Under Age 18

Information of Minors. The Services are not directed to or intended for use by anyone under the age of 18. In compliance with laws, we will not intentionally collect any Personal Information from minors under the age of 18. If you think that we have collected Personal Information from a minor, please contact us by e-mailing privacy@Onserahealth.com.

We do not knowingly collect personal data from anyone under the age of 13 through our Services, and our Services are not directed to children under the age of 13. If we discover we have received any “personal information” (as defined under the Children’s Online Privacy Protection Act) from a child under the age of 13 in violation of this Privacy Policy, we will take reasonable steps to delete that information as quickly as possible.


9. Privacy of Telecommunications Information

Onsera may obtain customer proprietary network information (CPNI) from certain affiliates or partners in connection with your use of the Services. CPNI is data collected by telecommunications companies that relates to the type, quantity, destination, technical configuration, location, and amount of use of telecommunications and interconnected VoIP services. In certain instances, Onsera may use CPNI provided by affiliates or partners to enhance or facilitate the Services provided to you. Onsera is fully committed to protecting the confidentiality of any CPNI it receives in connection with the Services. Under federal law, you are entitled to contact your telecommunications provider to opt-out of sharing CPNI. If you believe your CPNI has been shared with Onsera in error, please contact us by e-mailing privacy@Onserahealth.com. If we have a relationship with your telecommunications provider, we will advise your telecommunications provider of your complaint.


10. Applicability of Privacy Policy

Our Privacy Policy applies to all of the Services offered by Onsera but does not apply to Services offered by other third-party companies or individuals, including products or sites that may be linked from our Services. This Privacy Policy does not address, and we are not responsible for the privacy, information, or other practices of any third parties, including health care providers, the manufacturer of your mobile device, and any other third party mobile application or website to which the Application may contain a link. We encourage you to review the Notice of Privacy Practices of each Service Provider who provides you with Services and the privacy policies of each website and application you visit and use.


11. Compliance and Cooperation with Regulatory Authorities

We regularly review our compliance with our Privacy Policy. It is our intention to review and resolve all formal complaints, either with the proper regulatory authority or directly with our users.


12. California Privacy Rights

Residents of the State of California, under certain provisions of the California Civil Code, have the right to request from companies conducting business in California a list of all third parties to which the company has disclosed certain personally identifiable information as defined under California law during the preceding year for third-party direct marketing purposes. The company is not required to provide the above-described lists if it adopts and discloses its policy of not disclosing Personal Information to third-parties for their direct marketing purposes unless the customer first affirmatively agrees to the disclosure.

We do not share information with third-parties for their direct marketing purposes unless you affirmatively agree to such disclosure — typically by opting-in to receive information from a third-party. To prevent disclosure of your Personal Information for use in direct marketing by a third-party, do not opt-in to such use when you provide Personal Information through our Services. California customers may request further information about our compliance with this law by e-mailing privacy@Onserahealth.com.

California Do Not Track Notice. Some browsers have a “Do Not Track” feature that lets you tell websites and online services that you do not want to have your online activities tracked. Our websites and Services do not respond to “Do Not Track” signals as such browser features and industry standards are not uniform.

Do Not Track ("DNT") is a privacy preference that users can set in certain web browsers. We are committed to providing you with meaningful choices about the information collected on our Websites for third party purposes, and that is why we provide the variety of opt-out mechanisms listed herein. However, we do not currently recognize or respond to browser-initiated DNT signals.


13. Amendments to this Privacy Policy

Our Privacy Policy may be amended from time to time. This Privacy Policy is not intended to and does not create any contractual or other legal rights in or on behalf of any party. If we change this Privacy Policy, we will post changes on this page and, if the changes are material, we will provide a more prominent notice by sending you an email and/or posting a notice within the Application. Onsera reserves the right to modify this Privacy Policy at any time, so please review it frequently.

Last modified: ___ June, 2026


Category of Personal and/or Sensitive Personal Information
Purposes of Use
Categories of Third Parties to Which Ro “Shares” and “Sells” this Personal Information for Advertising/Analytics Purposes
Identifiers and contact information (e.g., name, address, email address, account names)
Service providers; our affiliates; health care providers and services; entities for legal and fraud prevention
Provide and manage the Services; Analyze and improve the Services; Advertising and marketing; Legal purposes
Advertising partners
Commercial and transactional information (e.g., information about the fact that you made a purchase)
Service providers; our affiliates; health care providers and services; entities for legal and fraud prevention
Provide and manage the Services; Analyze and improve the Services; Advertising and marketing; Legal purposes
Advertising partners
Financial information (e.g., credit card info collected by our payment processors)
 Payment processors; service providers; our affiliates; entities for legal and fraud prevention
Provide and manage the Services; Analyze and improve the Services; Legal purposes
We don't sell/share
Internet or other network or device activity (e.g., IP address, browsing history, app usage)
Service providers; our affiliates; entities for legal and fraud prevention
Provide and manage the Services; Analyze and improve the Services; Advertising and marketing; Legal purposes
Advertising partners
General geolocation information (e.g., city and state or zip code)
Service providers; our affiliates; entities for legal and fraud prevention
Provide and manage the Services; Analyze and improve the Services; Advertising and marketing; Legal purposes
Advertising partners
Physical characteristics (e.g., photos and videos of you)
Service providers; our affiliates
Provide and manage the Services; Analyze and improve the Services; Legal purposes
We don't sell/share
User-generated content (e.g., information you choose to post in our online forums)
Service providers; our affiliates; entities for legal and fraud prevention
Provide and manage the Services; Analyze and improve the Services; Legal purposes
We don't sell/share
Customer service data (e.g., information you provide through a chat or call with Ro's Care Team)
Service providers; our affiliates; health care providers and services; entities for legal and fraud prevention
Provide and manage the Services; Analyze and improve the Services; Legal purposes
We don't sell/share
Health information (e.g., information about which online visit you started)  
Service providers; our affiliates; health care providers and services; entities for legal and fraud prevention
Provide and manage the Services; Analyze and improve the Services; Advertising and marketing; Legal purposes
Advertising partners
Information about sex life and sexual orientation
Service providers; our affiliates; health care providers and services; entities for legal and fraud prevention
Provide and manage the Services; Analyze and improve the Services; Advertising and marketing; Legal purposes
Advertising partners
Government-issued identification and numbers
Service providers; our affiliates; health care providers and services; entities for legal and fraud prevention
Provide and manage the Services; Analyze and improve the Services; Legal purposes
We don't sell/share
Log-in credentials
Service providers; entities for legal and fraud prevention
Provide and manage the Services; Analyze and improve the Services; Legal purposes
We don't sell/share
Race/Ethnicity
Service providers; our affiliates; health care providers and services; entities for legal and fraud prevention
Provide and manage the Services; Analyze and improve the Services; Legal purposes
We don't sell/share
Contents of communications made via the Services
Service providers; our affiliates; health care providers and services; entities for legal and fraud prevention
Provide and manage the Services; Analyze and improve the Services; Legal purposes
We don't sell/share

Purposes of Use
Categories of Information
Product and service delivery:
To provide and deliver products and services, including fulfilling your order, troubleshooting, and personalizing our services.
Contact information, demographic data, payment information, content and files, identifiers and device information, geolocation data, log data, usage data, sensor data, inferences. Sensitive Information: Account access information, sensitive demographic data, contents of communications, health data.
Business operations:
To operate our business, such as billing, accounting, improving our internal operations, securing our systems, detecting fraudulent or illegal activity, and meeting our legal obligations.
Contact information, demographic data, payment information, content and files, identifiers and device information, geolocation data, log data, usage data, sensor data, inferences. Sensitive Information: Account access information, sensitive demographic data, contents of communications, health data.  
Product improvement, development, and research:
To improve our products and services and develop new products and services (including AI/ML) and conduct user research (surveys, interviews).
Contact information, demographic data, payment information, content and files, identifiers and device information, geolocation data, log data, usage data, sensor data, inferences. Sensitive Information: Account access information, sensitive demographic data, contents of communications, health data.  
Personalization:
To understand you and your preferences to enhance your experience and enjoyment using our services.
Contact information, demographic data, payment information, content and files, identifiers and device information, geolocation data, log data, usage data, sensor data, inferences. Sensitive Information: Account access information, sensitive demographic data, contents of communications, health data.
Customer support:
To provide customer support and respond to your questions.
Contact information, demographic data, payment information, content and files, identifiers and device information, geolocation data, log data, usage data, sensor data, inferences. Sensitive Information: Account access information, sensitive demographic data, contents of communications, health data.
Communications:
To send you information, including confirmations, invoices, technical notices, updates, security alerts, reminders, support, and administrative messages.
Contact information, demographic data, payment information, content and files, identifiers and device information, geolocation data, log data, usage data, sensor data, inferences. Sensitive Information: Sensitive demographic data, health data.
Marketing:
To communicate with you about new services, offers, promotions, rewards, contests, upcoming events, and other information about our services and those of our selected partners.
Contact information, demographic data, payment information, content and files, identifiers and device information, geolocation data, log data, usage data, sensor data, inferences. Sensitive Information: Sensitive demographic data, health data.
Advertising:
To display advertising to you.
Contact information, demographic data, payment information, content and files, identifiers and device information, geolocation data, log data, usage data, sensor data, inferences. Sensitive Information: Sensitive demographic data, health data.